Show filters
137 Total Results
Displaying 11-20 of 137
Sort by:
Attacker Value
Unknown
CVE-2024-2354
Disclosure Date: March 10, 2024 (last updated April 01, 2024)
A vulnerability, which was classified as problematic, was found in Dreamer CMS 4.1.3. Affected is an unknown function of the file /admin/menu/toEdit. The manipulation of the argument id leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-256314 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-22293
Disclosure Date: January 31, 2024 (last updated February 07, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andrea Tarantini BP Profile Search allows Reflected XSS.This issue affects BP Profile Search: from n/a through 5.5.
0
Attacker Value
Unknown
CVE-2023-46887
Disclosure Date: November 29, 2023 (last updated December 06, 2023)
In Dreamer CMS before 4.0.1, the backend attachment management office has an Arbitrary File Download vulnerability.
0
Attacker Value
Unknown
CVE-2023-46886
Disclosure Date: November 29, 2023 (last updated December 06, 2023)
Dreamer CMS before version 4.0.1 is vulnerable to Directory Traversal. Background template management allows arbitrary modification of the template file, allowing system sensitive files to be read.
0
Attacker Value
Unknown
CVE-2023-48017
Disclosure Date: November 18, 2023 (last updated November 25, 2023)
Dreamer_cms 4.1.3 is vulnerable to Cross Site Request Forgery (CSRF) via Add permissions to CSRF in Permission Management.
0
Attacker Value
Unknown
CVE-2023-32123
Disclosure Date: November 13, 2023 (last updated June 21, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Dream-Theme The7 allows Stored XSS.This issue affects The7: from n/a through 11.7.3.
0
Attacker Value
Unknown
CVE-2023-48063
Disclosure Date: November 13, 2023 (last updated November 17, 2023)
An issue was discovered in dreamer_cms 4.1.3. There is a CSRF vulnerability that can delete a theme project via /admin/category/delete.
0
Attacker Value
Unknown
CVE-2023-48060
Disclosure Date: November 13, 2023 (last updated November 17, 2023)
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/add
0
Attacker Value
Unknown
CVE-2023-48058
Disclosure Date: November 13, 2023 (last updated November 17, 2023)
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/run
0
Attacker Value
Unknown
CVE-2023-45797
Disclosure Date: October 30, 2023 (last updated November 04, 2023)
A Buffer overflow vulnerability in DreamSecurity MagicLine4NX versions 1.0.0.1 to 1.0.0.26 allows an attacker to remotely execute code.
0